
Lazarus Group Weaponizes Windows Kernel Zero-Day CVE-2026-68820 in Global Defense Espionage Campaign
North Korean threat actors are actively exploiting a use-after-free vulnerability in the Windows WinSock driver to deploy the FudModule rootkit against aerospace and defense targets.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-68820
- Source:
- Check Point Research
- Read Time:
- 5 min
Executive Summary
Recent intelligence from Check Point Research and Microsoft MSRC has confirmed the active exploitation of a critical zero-day vulnerability, tracked as CVE-2026-68820, by the North Korean-linked Lazarus Group. The campaign, a new iteration of the long-standing 'Operation Dream Job,' specifically targets employees within the defense, aerospace, and aviation sectors in Europe and India. By leveraging a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), attackers are gaining SYSTEM-level privileges to deploy sophisticated kernel-mode rootkits. This activity highlights a persistent trend where nation-state actors weaponize kernel vulnerabilities to bypass modern endpoint security solutions.
Threat Analysis
The Lazarus Group is utilizing fraudulent recruitment offers as the primary infection vector. Attackers reach out to high-value targets on professional networking platforms, posing as recruiters for major aerospace firms. The lure involves a PDF or executable disguised as a job description which, when opened, initiates a multi-stage infection chain. The ultimate goal is the deployment of the FudModule rootkit. According to SecurityWeek, this campaign is particularly dangerous because it targets Windows 11 builds 26100 and 26200, demonstrating the group's ability to stay current with the latest operating system updates.
Technical Details
CVE-2026-68820 is a use-after-free (UAF) vulnerability residing in afd.sys, the kernel-mode driver for Windows Sockets (WinSock). The exploit allows a local attacker to elevate their privileges from a standard user to SYSTEM. Once elevated, the Lazarus Group installs a new version of the FudModule rootkit. Technical analysis reveals that this version of FudModule includes advanced capabilities to disable Endpoint Detection and Response (EDR) telemetry by tampering with kernel callbacks. Furthermore, the rootkit has been updated to interfere with Windows Smart App Control, effectively blinding security software to subsequent malicious activities performed by the attackers.
Attribution Assessment
Intelligence analysts attribute this activity to the Lazarus Group (also known as Diamond Sleet or APT38) with high confidence. The attribution is based on the reuse of the 'Operation Dream Job' infrastructure, specific code overlaps in the FudModule rootkit, and the targeting of strategic sectors consistent with North Korean state interests. The use of kernel-level exploits to blind EDR is a hallmark of recent Lazarus operations, as noted in BleepingComputer's reporting.
Implications
The exploitation of CVE-2026-68820 represents a significant escalation in the threat landscape for the defense industrial base. Because the exploit operates at the kernel level, traditional user-mode security tools may fail to detect the initial compromise or the subsequent presence of the rootkit. The ability of the Lazarus Group to bypass EDR telemetry means that compromised organizations may suffer long-term, undetected data exfiltration, potentially compromising sensitive military and aerospace technologies.
Recommendations
Encrygma recommends that all organizations immediately apply the August 2026 Patch Tuesday updates provided by Microsoft, which address CVE-2026-68820. Security teams should also monitor for unusual activity involving afd.sys and audit for the presence of unauthorized kernel drivers. Additionally, high-value targets in the defense sector should be briefed on the risks of unsolicited recruitment offers and encouraged to verify the identity of recruiters through official corporate channels before opening any shared documents.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Exploitation Surge: Citrix NetScaler and F5 BIG-IP Under Active Attack

Critical Zero-Day Exploitation Campaign Targets Citrix NetScaler ADC and Gateway Appliances Globally

